
The AI act is upon us! But will it strike the right balance between innovation and protecting the rights of intellectual property rights owners and citizens enticed to use artifical intelligence in their daily lives? This is a difficult challenge to win and, further to our detailed analysis of the AI act, we have reached the conclusion that such AI act will throttle artificial intelligence in the European Union, forcing AI technological advancements and leaps to take place on other continents like the US or Asia. What a loss of technical and business opportunities and advancement for Europe, which, as always, is too conservative in its mindset for its own good.
1. What is the Artificial Intelligence Act?
Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (‟AI act”) is a regulation from the European Union (‟EU”) that provides a comprehensive, sector-agnostic, regulatory regime which forms the foundation of Artificial Intelligence (‟AI”) governance and regulation across the EU, with downstream implications for companies and developing legislation around the world.
The AI act is part of a ‟package” of new EU rules focused on achieving Europe’s digital targets for 2030 and the digital ecosystem ‟Shaping Europe’s digital future”, along with the Digital Markets Act, the Digital Services Act, as well as the Data Act and the Data Governance Act, which form a single set of rules that apply across the EU, to implement the two following goals:
- create a safer digital space in which the fundamental rights of all users of digital services are protected by setting clear and proportionate rules, and
- establish a level playing field to foster innovation, growth and competitiveness, both in the European single market and globally.
More specifically, spanning 180 recitals and 113 articles, the AI act is a tiered risk-based approach to regulating the entire lifecycle of different types of AI systems, with the following consequences:
- AI systems for certain uses will be prohibited;
- certain AI systems will be designated as High-Risk AI Systems (‟HRAIS”) and subject to extensive obligations, especially for AI providers;
- there are some specific provisions governing General Purpose AI (‟GPAI”) models, where those GPAI models are regulated regardless of use case, and
- other AI systems are considered low risk and therefore are subject only to limited transparency obligations when they interact with individuals.

The AI act is a result of extensive negotiation, aimed at laying down a harmonised legal framework ‟for the development, the placing on the market, the putting into service and the use of artificial intelligence systems” in the EU.
2. When does the AI act enter into force?
The AI act was published in the official journal of the EU on 12 July 2024, more than three years after the proposed original text was released by the EU commission (the ‟Commission”) in April 2021.
On 1 August 2024, the AI act entered into force.
Now that the AI act has been published, its requirements will take effect on a rolling basis over the next several years, as follows:
- By 2 February 2025, companies and businesses must stop all use and operation of AI systems that present unacceptable risk.
- By 2 August 2025, companies and businesses must ensure that all transparency requirements and obligations relating to any use of GPAI are met.
- By 2 August 2026, companies and businesses must ensure that all operational procedures for HRAIS are met and in place for existing and future AI systems.
- By 2 August 2027, companies and businesses must ensure all provided and deployed AI systems comply with sector-specific AI regulations and standards in existence within the EU.
- By 2 August 2030, the grace period for HRAIS intended for use by public authorities ends.
So, for example, organisations will have six months to ensure they do not use any AI systems or technologies that may pose unacceptable risk. Similarly, many organisations will have twenty-four months to ensure they have the operational requirements in place to develop, provide, and/or deploy HRAIS in a compliant manner (subject to certain exemptions outlined below).
As notable from the above-mentioned implementation timeline, most provisions in the AI act will apply after a two-year implementation period (i.e. from 2 August 2026). During this period, various supporting delegated legislation, guidance and harmonised standards developed by the European Standardisation Organisations, will be published to assist with the AI act compliance.
3. Who is affected and/or impacted by the AI act? AI systems
3.1. AI systems (article 3(1) AI act)
Most of the obligations under the AI act concern AI systems, which are broadly defined as ‟machine-based systems that are designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infer, from the input they receive, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments”.
The AI act establishes obligations for providers, deployers, importers, distributors and product manufacturers of AI systems, with a link to the EU market.
For example, the AI act applies to:
- providers which place on the EU market, or put into service, AI systems, or place on the EU market GPAI models;
- deployers of AI systems who have a place of establishment and/or are located in the EU;
- providers and deployers of AI systems in third countries, if the output produced by the AI system is being used in the EU (article 2(1) AI act).
The AI act also enumerates certain exceptions to its material scope: for example, the AI act does not apply to open-source AI systems, unless they are prohibited or classified as HRAIS or AI systems used for the sole purpose of scientific research and development (articles 2(3), 2(4), 2(6), 2(8), 2(10) and 2(12)).
EU member-states are able to maintain or introduce national regulations that are more favourable to workers in terms of protecting their rights in respect of the use of AI systems by employers, or encouraging or allowing the application of worker-friendly collective agreements (article 2(11)).
3.2. Prohibited AI systems (article 5 AI act)
The AI act bans certain AI practices across the EU, which it considers harmful, abusive and in contradiction with EU values.
The prohibited AI practices include:
- the deployment of subliminal AI techniques beyond a person’s consciousness or purposefully manipulative or deceptive techniques, with the objective, or the effect of, materially distorting human behaviour;
- AI systems for biometric categorisation and identification, including those for untargeted scraping of facial data from the internet;
- AI systems for emotion recognition in law enforcement, border management, the workplace and education, and
- AI systems for the social scoring evaluation or classification of natural persons or groups thereof over a period of time based on their social behaviour.
The AI act carves out a few exceptions, though, to this rule, for law enforcement purposes relating to the use of ‟real-time” remote biometric identification in publicly accessible spaces (article 5(2)).
3.3. High-Risk AI Systems – HRAIS (chapter III AI act)
The most onerous regulatory obligations under the AI act attach to HRAIS.
With the aim of implementing a proportionate and effective set of rules for AI systems, the AI act establishes a risk-based approach to regulation and categorises AI systems based on the intensity and scope of the risks each AI system can generate.
HRAIS, which are AI systems that present a ‟high” risk, fall within the two following categories:
- AI systems used as a safety component of a product (or otherwise subject to EU health and safety harmonisation legislation), and
- AI systems deployed in eight specific areas, including biometrics, critical infrastructure (e.g. water, gas and electricity supplies), education, employment, access to essential public and private services, law enforcement, migration, the administration of justice and the insurance and banking sectors (articles 6(1) and (2) and annex III AI act).
An AI system deployed in these eight specified areas is always considered high-risk if it performs profiling of natural persons (article 6(3)).
As a derogation, an AI system that falls within those eight specific areas may be deemed as not posing such a high risk if its intended use is limited to:
- performing narrow procedural tasks;
- making improvements to the results of previously completed human activities;
- detecting decision-making patterns or deviations from prior decision-making patterns without replacing or influencing human assessments, or
- mere preparatory tasks to a risk-assessment (article 6(3)).
The AI act imposes a wide range of obligations on the various actors in the lifecycle of a HRAIS, which include:
- requirements on data training and data governance;
- technical documentation;
- recordkeeping;
- technical robustness;
- transparency;
- human oversight, and
- accuracy, robustness and cybersecurity.
For example, HRAIS which make use of techniques involving the training of models with data will have to be developed on the basis of training, validation and testing data sets that meet the quality criteria set by article 10 AI act.
HRAIS providers will also be subject to various procedural obligations before they supply any HRAIS:
- CE marking: providers must ensure their HRAIS undergoes a conformity assessment procedure before the HRAIS is supplied, and affix a CE mark to its documentation;
- registration in the EU database: providers and public bodies using HRAIS must register HRAIS in an EU-wide database of AI systems, and
- reporting obligations: HRAIS providers must report serious incidents or malfunctioning involving their HRAIS to a relevant authority within 15 days.
Other operators of HRAIS will be subject to more limited obligations, such as to:
- complete fundamental rights impact assessments;
- ensure they use the HRAIS in accordance with its instructions of use;
- monitor the operation of the HRAIS, and
- keep a record of the logs generated by the HRAIS (if under their control).
Article 7 also provides for a process and some criteria for the addition of new, or the modification of existing, use cases for HRAIS by the Commission.
So, HRAIS are subject to extensive obligations, especially for providers. What about the specific provisions governing GPAI models?
3.4. General Purpose AI – GPAI – models (chapter V AI act)
AI technologies which are not prohibited or high-risk, will be subject to much less onerous regulatory requirements.
The most onerous other requirements under the AI act attach to GPAI. The requirements for most GPAI models, which include foundation models and generative AI models, are chiefly focused on transparency.
A GPAI model is defined as ‟an AI model, including where such an AI model is trained with a large amount of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks, regardless of the way the model is placed on the market and that can be integrated into a variety of downstream systems or applications, except AI models that are used for research, development or prototyping activities before they are placed on the market” (article 3(63)). This definition is vague and leaves room for interpretation to competent regulators, national legislators and courts (in particular what ‟significant generality” means).
The AI act will not apply to any AI systems or models (including GPAI models and their output) where they are specifically developed and put into service for the sole purpose of scientific research and development (article 2(6)).
The classification of GPAI models with systemic risk is addressed in article 51: a GPAI model is classified as a GPAI model with systemic risk if it has high impact capabilities (evaluated on the basis of appropriate technical tools and methodologies, including indicators and benchmarks) or is identified as such by the Commission. For example, a GPAI model is presumed to have high impact capabilities if the amount of computational power, measured in Floating Point Operations (‟FLOPs”), is greater than 10 (article 51(2)).
The provider of a GPAI model must notify the Commission if they become aware that a GPAI model does, or will, qualify as one with systemic risk without delay, and in any event within two weeks (article 52(1)). A list of AI models with systemic risk will be published and frequently updated by the Commission, without prejudice to the need to observe and protect intellectual property rights and confidential commercial information or business secrets in accordance with EU and/or member-state law (article 52(6)).
All providers of GPAI models are subject to certain obligations (article 53), such as:
- making available and maintaining up-to-date technical documentation, including its training and testing process, or providing information to AI system providers who intend to use the GPAI model;
- cooperating with the Commission and national competent authorities, and
- complying with national laws on copyright and related rights.
Providers of GPAI models with systemic risk have additional obligations, including the obligations to perform standardised model evaluations, assess and mitigate systemic risks, track and report incidents and ensure cybersecurity protection (article 55).
3.5. Other AI systems
Save for the above, and except where two specific exemptions apply (military or defence; research and innovation), the only binding requirement for other AI systems is a limited obligation of transparency. Providers must ensure that AI systems that are intended to interact with individuals are designed and developed in such a way that individual users are aware that they are interacting with an AI system.
There is, however, a general obligation on all deployers and providers of AI systems to ensure that their staff that deal with the operation and use of AI systems have sufficient AI literacy. The appropriate level of AI literacy depends on the education, expertise and technical knowledge or staff, as well as the context in which the relevant AI systems are to be used.
4. Penalties and sanctions (chapter XII AI act)
Organisations must consider whether they are subject to the AI act and, if so, how they intend to comply with their obligations.
If an organisation fails to implement the changes dictated by the AI act, or disregards their obligations once the AI act is fully in force, they may be subject to heavy penalties for non-compliance, such as:
- fines up to 35 million Euros, or 7 percent of global annual turnover of the preceding financial year (whichever is higher), for failure to comply with obligations relating to prohibited AI systems (article 99(3));
- fines up to 15 million Euros, or 3 percent of global annual turnover of the preceding financial year (whichever is higher), for failure to comply with obligations relating to GPAI or HRAIS (article 101), and
- fines up to 7.5 million Euros, or 1 percent of global annual turnover of the preceding financial year (whichever is higher), for supplying incorrect, incomplete or misleading information to governing bodies and/or authorities in response to their requests (article 99(5)).
For SMEs and start-ups, the fines for all the above are subject to the same maximum percentages or amounts, but whichever is lower (article 99(6)).
Articles 85 to 87 of the AI act also provide for the rights of natural and legal persons to lodge a complaint with a market surveillance authority, to obtain explanation of individual decision-making, and to report instances of non-compliance.
5. AI act: ‟promoting” innovation with a lot of caution
Though the AI act is primarily focused on governing organisations and individuals within the borders of the EU, it has broad international reach. Organisations far outside Europe, such as those operating within the US or Asia, may be subject to the AI act’s requirements even when they have no presence within an EU member-state.
So beyond its international reach, the EU’s approach to the regulation of AI is increasingly appearing to be the standard for governments and regulators across the world. For example, the states of Colorado and California, in the US, and other international jurisdictions such as Canada, have openly stated that they are aiming to map their approaches to their EU peers.
While the AI act openly says that it approaches AI regulation with a primary focus on preventing harm to the health, safety and fundamental rights of individuals within the EU, it covertly stifles creativity, innovation and risk-taking. Consequently, no AI company and/or system will originate from the EU, under such rules imposed by the AI act. All successful AI systems will come from the US and Asia, where regulations will be much weaker – if inexistent.
Maybe all EU citizens will feel ‟uber-comfy” and well protected by their nanny state but, meanwhile, the US and China will battle it out to win this current war on AI world domination. Sometimes, only by getting out of your comfort zone and risking it, can you make some substantial evolution and growth leaps. The EU has not taken this approach: I do not want to hear any whining and complaints, in 5 years’ time, when the US and Asia will be so far ahead of Europeans that their technological advancements attract all the wealth, progress, creativity and economic opportunities.
Crefovi regularly updates its social media channels, such as Linkedin, Twitter, Instagram, YouTube and Facebook. Check our latest news there!

